Jump to the main content block

【Vulnerability Alert】Julu Digital|HCM - SQL Injection

publish date : 2026-07-17 update date : 2026-07-17

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026071604073838 Publication Time 2026-07-16 16:32:39
Incident Type ANA-Vulnerability Alert Discovery Time 2026-07-16 16:32:39
Impact Level Low  
[Subject]
【Vulnerability Alert】Julu Digital|HCM - SQL Injection
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000010

【Julu Digital|HCM - SQL Injection】(CVE-2026-15804, CVSS: 8.8) The HCM system developed by Julu Digital contains an SQL Injection vulnerability. An authenticated remote attacker may inject SQL commands through specific parameters, affecting the confidentiality, integrity, and availability of database data.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

HCM versions 7 to 7.5.3 (exclusive)

HCM versions 8 to 8.1.7.1 (exclusive)

[Recommended Actions]

Please update HCM 7 to version 7.5.3 or later

Please update HCM 8 to version 8.1.7.1 or later

[Reference]

https://www.twcert.org.tw/tw/cp-132-11035-5c640-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: